chore(deps): bump the actions-deps group with 10 updates#678
Open
dependabot[bot] wants to merge 1 commit intomainfrom
Open
chore(deps): bump the actions-deps group with 10 updates#678dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the actions-deps group with 10 updates: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.14.1` | `2.15.0` | | [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `47.0.1` | `47.0.4` | | [taiki-e/install-action](https://github.com/taiki-e/install-action) | `2.67.18` | `2.68.15` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `6.0.0` | `7.0.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.32.0` | `4.32.4` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.18.0` | `6.19.2` | | [anchore/scan-action](https://github.com/anchore/scan-action) | `7.3.1` | `7.3.2` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `3.2.0` | `4.1.0` | | [iarekylew00t/verified-bot-commit](https://github.com/iarekylew00t/verified-bot-commit) | `2.1.2` | `2.1.6` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.22.1` | `0.23.0` | Updates `step-security/harden-runner` from 2.14.1 to 2.15.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@e3f713f...a90bcbc) Updates `tj-actions/changed-files` from 47.0.1 to 47.0.4 - [Release notes](https://github.com/tj-actions/changed-files/releases) - [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md) - [Commits](tj-actions/changed-files@e002140...7dee1b0) Updates `taiki-e/install-action` from 2.67.18 to 2.68.15 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](taiki-e/install-action@650c5ca...68675c5) Updates `actions/upload-artifact` from 6.0.0 to 7.0.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@b7c566a...bbbca2d) Updates `github/codeql-action` from 4.32.0 to 4.32.4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b20883b...89a39a4) Updates `docker/build-push-action` from 6.18.0 to 6.19.2 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@2634353...10e90e3) Updates `anchore/scan-action` from 7.3.1 to 7.3.2 - [Release notes](https://github.com/anchore/scan-action/releases) - [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md) - [Commits](anchore/scan-action@8d2fce0...7037fa0) Updates `actions/attest-build-provenance` from 3.2.0 to 4.1.0 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@96278af...a2bbfa2) Updates `iarekylew00t/verified-bot-commit` from 2.1.2 to 2.1.6 - [Release notes](https://github.com/iarekylew00t/verified-bot-commit/releases) - [Commits](IAreKyleW00t/verified-bot-commit@a98e193...b001460) Updates `anchore/sbom-action` from 0.22.1 to 0.23.0 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@deef08a...17ae174) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: tj-actions/changed-files dependency-version: 47.0.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: taiki-e/install-action dependency-version: 2.68.15 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: actions/upload-artifact dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: github/codeql-action dependency-version: 4.32.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: docker/build-push-action dependency-version: 6.19.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: anchore/scan-action dependency-version: 7.3.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: actions/attest-build-provenance dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: iarekylew00t/verified-bot-commit dependency-version: 2.1.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: anchore/sbom-action dependency-version: 0.23.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions-deps group with 10 updates:
2.14.12.15.047.0.147.0.42.67.182.68.156.0.07.0.04.32.04.32.46.18.06.19.27.3.17.3.23.2.04.1.02.1.22.1.60.22.10.23.0Updates
step-security/harden-runnerfrom 2.14.1 to 2.15.0Release notes
Sourced from step-security/harden-runner's releases.
Commits
a90bcbcUpdate readme (#637)f0a59d8Release v2.15.0 (#639)5ef0c07Merge pull request #635 from step-security/rc-34eb43c7bupdate agentUpdates
tj-actions/changed-filesfrom 47.0.1 to 47.0.4Release notes
Sourced from tj-actions/changed-files's releases.
Changelog
Sourced from tj-actions/changed-files's changelog.
... (truncated)
Commits
7dee1b0update: release-tagger action to version 6.0.6 (#2801)28b28f6update: release-tagger action to version 6.0.0 (#2800)875e6e5chore(deps): bump github/codeql-action from 4.31.10 to 4.32.2 (#2790)8cba46echore(deps): bump actions/setup-node from 6.1.0 to 6.2.0 (#2766)925972fchore(deps-dev): bump@types/nodefrom 25.0.0 to 25.2.2 (#2793)a98754bchore(deps): bump@stdlib/utils-convert-pathfrom 0.2.2 to 0.2.3 (#2795)9c13e73chore(deps): bump actions/checkout from 6.0.1 to 6.0.2 (#2777)caee9d9fix: Update test.yml (#2781)16d791cchore(deps-dev): bump@types/lodashfrom 4.17.21 to 4.17.23 (#2759)8e056dechore(deps-dev): bump eslint-plugin-jest from 29.11.0 to 29.12.1 (#2756)Updates
taiki-e/install-actionfrom 2.67.18 to 2.68.15Release notes
Sourced from taiki-e/install-action's releases.
... (truncated)
Changelog
Sourced from taiki-e/install-action's changelog.
... (truncated)
Commits
68675c5Release 2.68.15404af2dUpdatemise@latestto 2026.2.239ecba83Updateprek@latestto 0.3.49fb5bf7Updatecargo-binstall@latestto 1.17.62dc1234Release 2.68.146ddbe37Updatewasm-bindgen@latestto 0.2.1145e3c734Updatetypos@latestto 1.44.0f3481aaUpdate allowed lint lista3324fbRelease 2.68.139d7e67cUpdateuv@latestto 0.10.7Updates
actions/upload-artifactfrom 6.0.0 to 7.0.0Release notes
Sourced from actions/upload-artifact's releases.
Commits
bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testUpdates
github/codeql-actionfrom 4.32.0 to 4.32.4Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
89a39a4Merge pull request #3494 from github/update-v4.32.4-39ba80c47e5d84c8Apply remaining review suggestions0c20209Apply suggestions from code review314172eFix typocdda72dAdd changelog entriescfda84cUpdate changelog for v4.32.439ba80cMerge pull request #3493 from github/update-bundle/codeql-bundle-v2.24.200150daAdd changelog noted97dce6Update default bundle to codeql-bundle-v2.24.250fdbb9Merge pull request #3492 from github/henrymercer/new-repository-properties-ffUpdates
docker/build-push-actionfrom 6.18.0 to 6.19.2Release notes
Sourced from docker/build-push-action's releases.
Commits
10e90e3Merge pull request #1458 from crazy-max/git-auth-port5262538chore: update generated contentcd130e4preserve port in GIT_AUTH_TOKEN host806c751Merge pull request #1452 from crazy-max/update-yarn601a80bMerge pull request #1456 from crazy-max/auth-token-dyn-host8f7fd7cchore: update generated content710e335derive GIT_AUTH_TOKEN host from GitHub server URLc4ca848update yarn to 4.9.2ee4ca42Merge pull request #1398 from docker/dependabot/npm_and_yarn/tmp-0.2.4f1b3bb5chore: update generated contentUpdates
anchore/scan-actionfrom 7.3.1 to 7.3.2Release notes
Sourced from anchore/scan-action's releases.
Commits
7037fa0chore(deps): bump@actions/cachefrom 5.0.3 to 5.0.5 (#592)d4c1dcdchore(deps): bump@actions/tool-cachefrom 3.0.0 to 3.0.1 (#593)d7f5518chore(deps): update Grype to v0.107.1 (#594)e573fa1feat: add option to specify one or more grype config files (#589)4829feachore(deps): bump fast-xml-parser from 5.3.3 to 5.3.4 (#590)db5ac0echore(deps): bump release-drafter/release-drafter from 6.1.0 to 6.2.0 (#587)5b5f7cdchore(deps): update Grype to v0.107.0 (#588)9fc81f9chore(deps-dev): bump prettier from 3.8.0 to 3.8.1 (#584)d2e46d3chore(deps): bump peter-evans/create-pull-request from 8.0.0 to 8.1.0 (#585)1091f6bchore(deps-dev): bump tar from 7.5.6 to 7.5.7 (#586)Updates
actions/attest-build-provenancefrom 3.2.0 to 4.1.0Release notes
Sourced from actions/attest-build-provenance's releases.
Commits
a2bbfa2bump actions/attest from 4.0.0 to 4.1.0 (#838)0856891update RELEASE.md docs (#836)e4d4f7cprepare v4 release (#835)02a49bdBump github/codeql-action in the actions-minor group (#824)7c757dfBump the npm-development group with 2 updates (#825)c44148eBump github/codeql-action in the actions-minor group (#818)3234352Bump@types/nodefrom 25.0.10 to 25.2.0 in the npm-development group (#819)18db129Bump tar from 7.5.6 to 7.5.7 (#816)90fadfaBump@actions/corefrom 2.0.1 to 2.0.2 in the npm-production group (#799)57db8baBump the npm-development group across 1 directory with 3 updates (#808)Updates
iarekylew00t/verified-bot-commitfrom 2.1.2 to 2.1.6Release notes
Sourced from iarekylew00t/verified-bot-commit's releases.
... (truncated)
Commits
b001460chore: Bumping version to v2.1.687bfaefbuild(deps): Bump@octokit/plugin-retryfrom 8.0.3 to 8.1.0 (#293)5b7bc78build(deps): Bump minimatch from 10.2.3 to 10.2.4 (#297)508d8a5build(deps): Bump minimatch from 10.2.2 to 10.2.3 (#296)1b47288build(deps): Bump github/codeql-action from 4.32.3 to 4.32.4 in the actions g...45bbcdebuild(deps-dev): Bump the npm-development group with 4 updates (#291)a2269b7chore: Bumping version to v2.1.5d9d9559fix: Allow glob patterns to match dotfiles (#289)0e12e78build(deps-dev): Bump the npm-development group with 4 updates (#285)c723cf4build(deps): Bump mi...Description has been truncated